PatchSiren

Openfind CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Openfind CVE published 2026-10-08

CVE-2026-107459

CVE-2026-107459 is an OS Command Injection vulnerability in Openfind's SecuShare Pro. Unauthenticated remote attackers can inject and execute arbitrary OS commands on the server. This critical vulnerability has a CVSS score of 9.3. The vulnerability allows attackers to execute arbitrary OS commands without authentication, potentially leading to system compromise. System administrators and security teams m [truncated]

HIGH Openfind CVE published 2026-04-16

CVE-2026-6351

CRLF injection vulnerability in MailGates/MailAudit by Openfind enables unauthenticated remote attackers to read system files. Published 2026-04-16; modified 2026-05-19. CVSS 4.0 vector indicates network attack vector with low complexity, no privileges required, and high confidentiality impact. CISA KEV: Not listed.

CRITICAL Openfind CVE published 2026-04-16

CVE-2026-6350

A critical stack-based buffer overflow vulnerability exists in MailGates/MailAudit, email security products developed by Openfind. The flaw allows unauthenticated remote attackers to hijack program execution flow and execute arbitrary code. The vulnerability was disclosed by Taiwan's Computer Emergency Response Team/Coordination Center (TWCERT/CC) and carries a CVSS 4.0 score of 9.3 (Critical). As of the [truncated]